← WordPress Vulnerabilities
WordPress security by component

Robo Gallery – Photo & Image Slider

Robo Gallery – Photo & Image Slider is a WordPress component with 17 published CVE records in this archive. The latest tracked vulnerability was published Apr 08, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: robo-gallery

CVE-2026-4300: Robo Gallery – Photo & Image Slider: Cross-site scripting

Robo Gallery – Photo & Image Slider is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 5.1.3.

PublishedApr 08, 2026
Known safe version> 5.1.3
Safe version
Apr 08, 2026 CVE-2026-4300
Robo Gallery – Photo & Image Slider: Cross-site scripting
Robo Gallery – Photo & Image Slider is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 5.1.3.
> 5.1.3
CVE6.4
NVDPending
Mar 13, 2026 CVE-2026-32356
Robo Gallery: Cross-site scripting
Robo Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
May 15, 2025 CVE-2024-13384
Photo Gallery, Images, Slider in Rbs Image Gallery: Cross-site scripting
Photo Gallery, Images, Slider in Rbs Image Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
May 15, 2025 CVE-2024-10144
Photo Gallery, Images, Slider in Rbs Image Gallery: Cross-site scripting
Photo Gallery, Images, Slider in Rbs Image Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
May 07, 2025 CVE-2025-47521
Robo Gallery: Cross-site scripting
Robo Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Jan 07, 2025 CVE-2024-10102
Photo Gallery, Images, Slider in Rbs Image Gallery: Cross-site scripting
Photo Gallery, Images, Slider in Rbs Image Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE2.7
NVDPending
Dec 13, 2024 CVE-2022-45841
Robo Gallery: A security weakness
Robo Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Oct 24, 2024 CVE-2024-49696
Robo Gallery: Cross-site scripting
Robo Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Oct 08, 2024 CVE-2024-8431
Photo Gallery, Images, Slider in Rbs Image Gallery: A security weakness
Photo Gallery, Images, Slider in Rbs Image Gallery is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jul 24, 2024 CVE-2024-3896
Photo Gallery, Images, Slider in Rbs Image Gallery: Cross-site scripting
Photo Gallery, Images, Slider in Rbs Image Gallery is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 19, 2024 CVE-2024-5343
Photo Gallery, Images, Slider in Rbs Image Gallery: Cross-site request forgery
Photo Gallery, Images, Slider in Rbs Image Gallery is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVDPending
May 06, 2024 CVE-2024-34382
Robo Gallery: A security weakness
Robo Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Jan 31, 2024 CVE-2024-22295
Photo Gallery, Images, Slider in Rbs Image Gallery: Cross-site scripting
Photo Gallery, Images, Slider in Rbs Image Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD5.4
Sep 04, 2023 CVE-2023-3499
Photo Gallery, Images, Slider in Rbs Image Gallery: Cross-site scripting
Photo Gallery, Images, Slider in Rbs Image Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
May 20, 2023 CVE-2023-24414
Robo Gallery: Cross-site request forgery
Robo Gallery is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
Apr 07, 2023 CVE-2023-27620
Robo Gallery: Cross-site scripting
Robo Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Mar 01, 2023 CVE-2022-45804
Robo Gallery: Cross-site request forgery
Robo Gallery is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD5.4